-
Right now snyk is listed as a dependency in the package.json. This causes snyk to be installed in every project using this tool.
I think it should be a devDependency instead. That should work since t…
-
There is currently no tooling in the ci pipeline that checks for vulnerabilties in the dependencies. As far as I know there are two available tools out there, snyk.io and npm audit, that can do this f…
-
When man uses conftest push to GCR, created date is "Jan 1, 1970"
conftest Version: 0.17.1(Commit: 45177b4)
Expected
current date
In fact
![image](https://user-images.githubusercontent.com/61…
lopeg updated
4 years ago
-
# 🚀 Feature Request
### Relevant Package
Can apply to any part of EdgeX framework. Most directly relevant to security services.
### Description
The project does not have an objective means of…
-
The purpose of this spike would be to research and document any security concerns that must be addressed for VANotify prior to going into production
- [x] Consult with VA/VSP teams to understand and …
-
Would love to use in my organization, but our internal tooling will not allow packages with a dependency on this version of Jackson. Is there way for me to force an upgrade to a newer version?
Not …
-
# Bug Report
## Problem
Snyk (https://www.npmjs.com/package/snyk) querying a database of known vulnerabilities revealed this critical security vulnerability:
```
✗ High severity vulnerabilit…
-
- **Library Version**:
![Screen Shot 2020-02-06 at 3 34 36 PM](https://user-images.githubusercontent.com/60762804/73991227-cf050480-4908-11ea-909d-a46f6e3b8315.png)
- **OS**: MacOS v 10.14.6
…
-
when running ods-quickstarter tests,
docgen jenkinsfile is executed and tests seems fails.
this is the output log
```
OpenShift Build unitt-cd/run-unitt-docgen-unitt-3x-2 from https://bitbucket/sc…
-
See screenshot, looks like a sub-dependency of some dev-dependencies. Lerna and Sass look like the main culprits here.